← Back

Valgrind

valgrind

Vendor: Jenkins • 2 CVEs

CVEs (2)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Jenkins
1Valgrind
Nov 21, 2024
Sep 1, 2020
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Jenkins Valgrind Plugin 0.28 and earlier does not escape content in Valgrind XML reports, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to control Valgrind XML report conten...Show more
Jenkins Valgrind Plugin 0.28 and earlier does not escape content in Valgrind XML reports, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to control Valgrind XML report contents.Show less
1Jenkins
1Valgrind
Nov 21, 2024
Sep 1, 2020
N/A· v4
7.1 HIGH· v3
5.5 MEDIUM· v2
Jenkins Valgrind Plugin 0.28 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.